5.4
CVSSv3

CVE-2018-10580

Published: 11/05/2018 Updated: 14/06/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displays that user's most recent posts without sanitizing the tsubject (aka thread subject) field.

Vulnerable Product Search on Vulmon Subscribe to Product

latest posts on profile project latest posts on profile 1.1

Exploits

# Exploit Title: MyBB Latest Posts on Profile Plugin v11 - Cross-Site Scripting # Date: 4/20/2018 # Author: 0xB9 # Contact: luxorforumscom/User-0xB9 or 0xB9[at]pmme # Software Link: communitymybbcom/modsphp?action=view&pid=914 # Version: 11 # Tested on: Ubuntu 1710 # CVE: CVE-2018-10580 1 Description: Adds a new section to us ...
MyBB Latest Posts on Profile plugin version 11 suffers from a cross site scripting vulnerability ...